Skip to content
Back

Attack Surface Management for Enterprise: How Leaf Home Gained an Attacker's View of Its External Risk

Asaf Rousseau

September 2, 2026
Success Story
Share

Leaf Home is the world's largest direct-to-consumer home improvement company. Serving more than 2 million homeowners across the U.S. and Canada with gutter protection, water filtration, stair lifts, bath solutions, and home enhancement services, the company operates through a nationwide network of over 290 office locations and 10,000 employees.

At $2.5 billion in annual revenue, Leaf Home is not a small business with a simple IT footprint. It is a large enterprise that has scaled rapidly through organic growth and frequent acquisitions - and every acquisition brought new brands, new applications, and new digital assets that expanded the external attack surface faster than a small security team could track.

As Todd Eldredge, Head of Cybersecurity, IAM & GRC at Leaf Home, put it: "Your tooling is only as good as what you can actually see. If something exists outside of that view, it might as well not exist to your security program - but attackers will still be able to see it."

That gap between what the security team could see and what attackers could see was the problem ULTRA RED was brought in to close.

The Challenge: Security at the Pace of Growth

Home improvement companies at enterprise scale face security challenges that are structurally different from software companies or financial services firms. The environment is distributed, field-based, and M&A-driven - and it produces attack surface characteristics that traditional security tools handle poorly.

  • Rapid acquisition of new brands: Each acquired business brings its own domains, applications, and digital infrastructure. Assets are introduced faster than security teams can formally onboard them into monitoring programs.

  • 290+ office locations across the U.S. and Canada: Distributed operations mean distributed IT. What is deployed at a regional office may not be visible to a central security team - and may never have been formally registered in any asset inventory.

  • Lean security team, large environment: Leaf Home's cybersecurity team is small relative to the scale of the environment it protects. Every hour spent validating alerts or chasing false positives is an hour not spent on real risk reduction.

  • Known-asset dependency in existing tools: The digital risk and monitoring tools already in place at Leaf Home depended on manually fed data - domains and assets the team already knew about. Unknown assets, forgotten subdomains, and acquired infrastructure fell outside their scope entirely.

  • Consumer data at scale: With over 2 million customers and payment and personal data flowing across hundreds of locations, the consequences of an undetected external exposure are significant.

Why Existing Tools Left Blind Spots

Leaf Home already had digital risk and monitoring tools in place before deploying ULTRA RED. The problem was not a lack of tooling - it was the fundamental limitation of how those tools worked.

As Eldredge explained: "We already had a digital risk platform, but those tools only work with the data you give them. With ULTRA RED, we provided some initial domains and then it went out and found far more than we expected. That was eye-opening."

Traditional vulnerability management and point-in-time penetration testing have the same dependency: they require a known scope to work from. Anything outside that scope - an asset registered under an acquired brand's domain, a forgotten subdomain from a past campaign, an externally facing internal application - remains invisible.

Unknown asset discovery is the capability that changes this. ULTRA RED starts from the internet, not from an internal asset list. Using seed domains and IP ranges as starting points, it autonomously maps the full external footprint - finding assets the team did not know existed alongside the ones they did.

What ULTRA RED Found

ULTRA RED was deployed as part of a proof of value, and results appeared within days.

  • Critical vulnerability in an internally developed application: ULTRA RED identified a significant vulnerability that other tools had missed entirely. The finding was not just flagged - it was fully validated, complete with technical evidence and remediation context ready to hand directly to the web development team. Eldredge noted: "ULTRA RED didn't just send us alerts and ask us to investigate. They handed us verified, actionable findings with evidence, ready to give straight to our web development team. Our involvement was minimal."

  • Unknown external websites and suspicious redirects: ULTRA RED uncovered external assets that no one internally recognized or could explain - websites and redirect chains associated with Leaf Home's organization that had not appeared in any existing security inventory. In Eldredge's words: "That's exactly the kind of thing we need to see because if we don't see it, we can't act on it."

How Validation Changes the Economics of a Lean Security Team

The operational impact of validation-first External Attack Surface Management is most visible in organizations where security team capacity is constrained relative to the environment size - which describes most home improvement and home services enterprises.

When every finding that reaches the queue is already confirmed exploitable, the team's work changes. Instead of validating alerts, re-testing vulnerabilities, and debating false positives, the team moves directly to remediation.

Eldredge described it directly: "ULTRA RED acts as a force multiplier for our team. We don't have to validate, double-check, or chase false alerts. Everything is fully vetted out, which is huge for a small team supporting a growing organization."

And at the individual level: "I have a small team and a very large attack surface. We don't have time to validate every alert manually. Being able to trust the data and immediately act on it saves enormous time and effort and removes a massive burden from our workload."

ULTRA RED's Continuous Threat Exposure Management platform runs continuously and operates agentlessly - no agents to deploy, no internal network access required, no ongoing maintenance overhead. For a lean team managing a large, distributed environment, the operational model matters as much as the capability.

Attack Surface Management for M&A-Driven Growth

One of the specific use cases Leaf Home identified was M&A security acceleration. Every acquisition introduces an attack surface that was secured to the acquired company's standards - not Leaf Home's. Without outside-in discovery, inherited risk from acquisitions can remain invisible for months after a deal closes.

ULTRA RED's ability to scope a newly acquired entity from a seed of domains - and immediately map its external footprint without internal access - gives security teams visibility into inherited risk at the speed of the business.

Leaf Home is now fully onboarding ULTRA RED across its environment, with plans to expand usage across brands and future acquisitions. As Eldredge put it: "We already see a lot of value and clearly understand the vision. As we continue to scale, having validated visibility into our external risk is only going to become more important."

For more on how EASM supports M&A security due diligence, see EASM for Mergers and Acquisitions.

Attack Surface Management at Enterprise Scale: What Works

The Leaf Home deployment illustrates several principles that apply across large, distributed enterprise environments:

  • Start from the attacker's perspective: Outside-in discovery finds what internal tools miss. Provide seed domains and let the platform map the full external footprint - including subsidiary, acquired, and forgotten assets.

  • Validate before you prioritize: Prioritization based on confirmed exploitability focuses remediation effort on real risk. CVSS scores and version-based findings without validation create noise that consumes team capacity without reducing exposure.

  • Run continuously, not periodically: An attack surface that grows through ongoing acquisitions and new deployments needs continuous monitoring. Point-in-time assessments go stale in days in fast-moving environments.

  • Treat the security team as a constrained resource: Platforms that require manual validation transfer work from the tool to the team. Validation-first platforms transfer work in the other direction - acting as a force multiplier for lean security functions.

  • Scope acquisitions immediately post-close: The window between deal close and full security integration is the highest-risk period. Outside-in discovery that requires no internal access closes that window faster than agent-based approaches.

Frequently Asked Questions

What is attack surface management for home improvement or home services companies?

Attack surface management for home improvement companies means continuously discovering all internet-facing assets across hundreds of locations, multiple brands, and acquired businesses - then validating which exposures are actually exploitable before attackers find them. The outside-in approach is essential because internal asset inventories consistently miss assets registered under acquired brands or deployed by regional teams without central IT involvement.

How does M&A activity create attack surface risk?

Each acquisition introduces new domains, applications, cloud environments, and technical debt that may have been secured to a different standard. Without outside-in discovery, these inherited assets remain invisible to the acquiring company's security program - creating exposure that attackers can find even when the security team cannot.

How does a small security team manage a large attack surface?

Validation-first platforms change the equation. When every finding that reaches the queue is already confirmed exploitable - with evidence - the team skips triage and moves directly to remediation. ULTRA RED's agentless operation also eliminates the maintenance overhead that scales linearly with environment size on agent-based platforms.

What is the difference between asset discovery and attack surface management?

Asset discovery identifies what exists. Attack surface management adds continuous monitoring, exposure validation, and prioritized remediation context. The goal is not a complete inventory - it is knowing which assets are exposed, which exposures are actually exploitable, and what to fix first.

Why do point-in-time penetration tests fall short for large enterprises?

Point-in-time tests scope from a known asset list and test the environment as it exists during the engagement window. In environments that grow through frequent acquisitions and new deployments, the tested state diverges from the actual state within days. Continuous outside-in monitoring closes this gap.

See what ULTRA RED surfaces across distributed enterprise environments. Book a demo or explore the platform.

Related: Unknown Asset Discovery | EASM for Mergers and Acquisitions | What Is External Attack Surface Management? | EASM Platform Guide

Asaf Rousseau